Impact
A vulnerability exists in Oracle Landed Cost Management that allows an attacker with only low privileges and network access via HTTP to compromise the application. The flaw permits the attacker to read critical data, obtain complete access to the data available to the application, and perform unauthorized updates, inserts or deletes. The impact is a loss of confidentiality for sensitive cost data and a compromise of data integrity.
Affected Systems
The affected vendor is Oracle Corporation, specifically the Oracle Landed Cost Management component of Oracle E‑Business Suite. Versions 12.2.3 through 12.2.15 are vulnerable.
Risk and Exploitability
The CVSS 3.1 Base Score of 7.1 indicates a high severity, with confidentiality impact rated high and integrity impact low. The attack vector is network, available from any host that can reach the HTTP interface, and the required privileges are low. The EPSS score of 0.00316 indicates a very low, but non-zero, likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The combination of a network-based exploitation path and low requirement for privileges raises the likelihood of actual attacks, especially in environments where the Oracle Landed Cost Management service is exposed to untrusted hosts.
OpenCVE Enrichment